Virtual Machine Isolation for Encrypted Virus Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current virus detection methods, such as signature scanning and emulation, are inadequate in detecting randomly encrypted and polymorphic viruses, leading to incomplete protection against malicious code, and require resource-intensive processes and frequent updates.
Innovation Solution
A method and system utilizing virtual machines for secure network access, where a virtual machine is provisioned to analyze content, detect viruses, and isolate potential threats, decoupling client risk and allowing centralized antivirus management, enabling anonymous network access and controlled access policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If signature scanning is used to detect viruses, then detection capability is improved, but resource consumption increases and detection precision deteriorates against encrypted viruses
Solution Approach 1:
The patent segments the scanning process into two distinct phases: an initial fast scan using virus signatures on file headers and known patterns, and a subsequent emulation scan on suspicious sections. This segmentation allows the system to maintain low resource consumption during routine scanning while allocating resources intensively only when needed, resolving the contradiction between detection capability and resource usage.
Solution Approach 2:
The patent introduces an intermediary emulation environment that acts as a mediator between the file system and the virus detection engine. This intermediary layer executes suspicious code in a controlled virtual environment, allowing detection of encrypted and polymorphic viruses without requiring resource-intensive scanning of entire files, thus improving detection precision while managing resource consumption.
2Measurement precision
If emulation is used to detect encrypted viruses, then detection precision is improved, but viruses may execute before detection causing infection
Solution Approach 1:
The patent applies preliminary action by performing fast signature-based scanning on file headers and known patterns before initiating emulation. This preliminary detection phase identifies obviously malicious files and suspicious sections that require emulation, allowing the system to prepare and control the emulation process before the virus can execute, thus preventing infection while maintaining high detection precision.
Solution Approach 2:
The patent implements preliminary anti-action by establishing a controlled emulation environment with pre-configured security measures before executing suspicious code. The emulation sandbox is prepared in advance with restricted system access and monitoring capabilities, preventing viruses from executing harmful actions even if they decrypt themselves during emulation, thereby counteracting the potential harm before it occurs.
3Reliability
If comprehensive virus scanning is performed, then protection coverage is improved, but system resources are excessively consumed
Solution Approach 1:
The patent applies partial action by performing comprehensive virus scanning only on suspicious file sections identified during the initial fast scan, rather than scanning entire files. The emulation process focuses specifically on questionable code segments, maintaining high protection coverage while significantly reducing system resource consumption compared to exhaustive scanning of all files.
4Reliability
If emulators are used for virus detection, then detection capability is improved, but viruses may become aware of emulators and avoid detection
Solution Approach 1:
The patent applies parameter changes by dynamically modifying emulation parameters such as execution timing, memory allocation, and system interface behavior. By varying these parameters across multiple emulation attempts, the system can detect viruses that attempt to identify static emulation environments, maintaining detection capability against adaptive viruses while preserving the benefits of emulation-based detection.
Data Source
AI summary
A method and apparatus for secure network access using a virtual machine are disclosed. The method includes provisioning a virtual machine, downloading content to the virtual machine, and sending information from the virtual machine. The information that is sent from the virtual machine is configured to allow the display of output from the virtual machine. The output from the virtual machine is based on the content. The apparatus includes a number of virtual machine servers. Each of the virtual machine servers is configured to support at least one of a number of virtual machines. A first virtual machine of the virtual machines includes an antivirus module. The first virtual machine is configured to download content. The antivirus module is configured to detect a virus by virtue of being configured to analyze the content.


